CVE-2019-11708
Mozilla Firefox and Thunderbird Sandbox Escape Vulnerability
- Published
- Jul 23, 2019
- Updated
- Oct 21, 2025
- Assigning CNA
- mozilla
- Evidence observed
- Dec 7, 2019
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HHigh · next 30 days
- Percentile
- 99.0%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process. When combined with additional vulnerabilities this could result in executing arbitrary code on the user's computer. This vulnerability affects Firefox ESR < 60.7.2, Firefox < 67.0.4, and Thunderbird < 60.7.2.
Sources
2- CVE-2019-9791Exploit
Exploit chain for CVE-2019-9791 & CVE-2019-11708 against firefox 65.0 on windows 64bit
Axel Souchet · windows_x86-64 · Dec 7, 2019
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.